IACR paper details

We give a closed formula for the Tate-pairing on
the hyperelliptic curve $y^2 = x^p - x + d$ in characteristic $p$.
This improves recent implementations by Barreto et.al. and
by Galbraith et.al. for the special case $p=3$.
As an application, we propose a $n$-round key agreement protocol
for up to $3^n$
participants by extending Joux's pairing-based protocol to
$n$ rounds.